All the latest UK technology news, reviews and analysis

Apple issues iOS security updates for jailbreak flaws

by Shaun Nichols

15 Jul 2011

Be the first to comment

  • Tweet this

Apple has released two security updates to address flaws in iOS including a vulnerability which was recently used to perform automatic 'jailbreak' hacks.

The company issued the iOS 4.3.4 update on Friday along with an iOS 4.2.9 security fix for older models.

The iOS update fixes two flaws in the CoreGraphics component which could allow a third party to use a malformed PDF file to access the device and remotely install code.

The vulnerability drew headlines earlier this month when researchers used one of the flaws to set up an automatic 'jailbreak' site which allowed iPad and iPhone owners to remove protections on the device and run software not authorised by Apple.

The flaw had been exploited only for voluntary jailbreaks which could be reversed with a software restore, but security researchers were worried that malware writers could use the vulnerability to install malware on iOS devices.

Also addressed in the update is an elevation of privilege vulnerability in the IOMobileFrameBuffer component. Apple warned that, if exploited, the vulnerability could allow malicious code to access the device running with the privileges of the user.

The updates can be obtained by connecting the iOS device to a PC or Mac running iTunes.

Apple's update comes at the end of a busy week for security fixes. Microsoft issued a monthly update to address 22 security vulnerabilities on Tuesday, and RIM released a fix for the BlackBerry Enterprise Server platform later in the week No BlackBerry smartphones or tablets were affected by that update.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

40%

0%

10%

50%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Java Developer, Algo Trading, FX, Trading Strategies

Java Deveoper/Programmer/Software Engineer, Algo Trading...

Lead and Senior Developers Wanted

Austin Fraser has the pleasure of appointing a number...

Java Developer - Great move up for a Junior Developer

Austin Fraser has the pleasure of appointing a Java Developer...

Senior J2EE Application Developer

Austin Fraser has the pleasure of appointing a Senior...

To send to more than one email address, simply separate each address with a comma.